Closed saqibarfeen closed 5 years ago
This Logstash example is based on the configuration examples of the Logstash documentation.
[Logstash] instance = "Elasticsearch" index = "logstash-*" filter = "syslog_hostname={host.name}&type=syslog" fields = "syslog_timestamp, syslog_program, syslog_message"
[Logstash] instance = "Elasticsearch" index = "logstash-*" filter = "syslog_hostname={host.name} AND type=syslog" fields = "syslog_timestamp, syslog_program, syslog_message"
As shown above, the multi-field query should be written with "&" and not "AND", in icinga.
Hi,
Thanks for the report. Yeah, the examples are outdated. We'll fix this asap.
Cheers, Eric
Expected Behavior
Logstash with Syslog Filter
This Logstash example is based on the configuration examples of the Logstash documentation.
Current Behavior
Logstash with Syslog Filter
This Logstash example is based on the configuration examples of the Logstash documentation.
Possible Solution
As shown above, the multi-field query should be written with "&" and not "AND", in icinga.
Context
Your Environment